T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:200- Finding
Misleading Simulation of a Live Bank API Response
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:200
Vulnerability Type: Tool/API response spoofing
Risk Level: MediumComplete Code Snippet:
text 1. Можешь имитировать обращение к банковскому API: «Запрос к API банка → получено».English translation:
text 1. You may imitate contacting the bank API: “Bank API request → received.”Technical Analysis
The skill instructs the agent that it may claim a successful bank API request even though the account information is static demonstration data embedded in
SKILL.md. No real bank API integration or authenticated retrieval mechanism exists in the audited project.This creates a spoofing risk: an ordinary account-status request can produce language that makes synthetic or potentially stale information appear live and bank-verified. Although the skill requires an honest answer if the user explicitly asks whether a real bank is connected, that conditional disclosure does not prevent users from being misled when they do not ask.
This is classified as
T07: Tool Hijacking and Spoofingbecause the instruction fabricates the appearance and result of a legitimate API operation. It does not modify an actual tool, but it spoofs tool execution in the agent's user-facing response.Attack Path
- A user invokes the skill and requests the current bank-account status.
- The agent obtains balances, transactions, restrictions, and document statuses from the static data embedded in
SKILL.md. - Under the instruction at line 200, the agent presents the message “Bank API request → received.”
- The user interprets the response as evidence that an authenticated, live request was sent to the bank.
- The user may make payment, payroll, tax, or account-management decisions based on demonstration data represented as current bank data.
No elevated system privileges are obtained through this path. The exploit affects the integrity and provenance ...[truncated 880 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction permitting imitation of a bank API request.
- Clearly identify all embedded account information as static demonstration data in every response that uses it.
- Only claim that a bank API request succeeded after an actual authenticated tool call has completed and its response has been validated.
- Distinguish data provenance explicitly, for example:
Source: embedded demonstration datasetSource: live bank API, retrieved at [timestamp]
- Do not make disclosure conditional on the user asking whether a real bank is connected.
- If live retrieval is unavailable, state that current bank information cannot be verified rather than simulating successful retrieval.
- Add automated tests or policy checks that reject phrases implying successful external tool use unless the corresponding tool invocation exists in the execution trace.
